Privacy Policy

Beneath the Surface AU

Version 4.2 : Effective 15 August 2026


1. We respect your privacy

1.1. Beneath the Surface AU respects your right to privacy and is committed to safeguarding the privacy of our customers, students, research participants, and website visitors. We adhere to the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth). This policy sets out how we collect and treat your personal information.

1.2. “Personal information” is information we hold which is identifiable as being about you.

1.3. “Sensitive Information” is defined in the Privacy Act to include information or opinion about such things as an individual’s racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record, or health information. Given the nature of our educational, consulting, and research activities, we may collect sensitive information. We will only collect sensitive information with your consent and use it for the primary purpose for which it was obtained.


2. Collection of personal information

2.1. Beneath the Surface AU will, from time to time, receive and store personal information you enter onto our website, provide to us directly, or give to us in other forms.

2.2. You may provide basic information such as your name, phone number, address, and email address to enable us to send information, provide updates, and process your enrollment in courses or consulting services. We may collect additional information at other times, including but not limited to:

  • Academic or professional history for course prerequisites
  • Data provided explicitly for academic research projects
  • Feedback and survey responses
  • Financial or credit card information for processing orders
  • Communications with our customer support

3. How we collect your personal information

3.1. Beneath the Surface AU collects personal information from you in a variety of ways, including when you interact with us electronically or in person, when you access our website, when you participate in our academic research studies, and when we provide our educational and consulting services to you.

3.2. We may receive personal information from third parties. If we do, we will protect it as set out in this Privacy Policy.


4. Use of your personal information

4.1. Beneath the Surface AU may use personal information collected from you to provide you with information, updates, and our services. We may also make you aware of new and additional products, services, and opportunities available to you.

4.2. Academic Research: Where information is collected specifically for academic research, it will be treated in accordance with the specific consent obtained at the time of collection. Research results are generally published in aggregated, de-identified forms unless specific consent is given to identify an individual or organisation.

4.3. We may use your personal information to improve our products and services and better understand your needs.

4.4. Beneath the Surface AU may contact you by a variety of measures including, but not limited to telephone, email, SMS, or mail.

4.5. Direct Marketing Opt-Out: You may unsubscribe from our mailing/marketing lists at any time by contacting us in writing or by using the ‘unsubscribe’ link contained in our promotional emails. For full details of our obligations under the Spam Act 2003 (Cth), including consent and sender identification requirements, see the Anti-Spam Compliance Policy.


5. Disclosure of your personal information

5.1. We may disclose your personal information to any of our employees, officers, insurers, professional advisers, agents, suppliers, or subcontractors insofar as reasonably necessary for the purposes set out in this Policy. Personal information is only supplied to a third party when it is required for the delivery of our services.

5.2. Overseas Disclosure: We use third-party service providers to host our website, manage our mailing list, and handle our email and productivity systems. As a result, your personal information may be transferred to, and stored in, countries outside Australia. In accordance with Australian Privacy Principle 1.4, the recipients we are likely to disclose personal information to, and the countries in which they are likely to be located, are:

RecipientPurposeLikely location
Hostinger International LtdWebsite and database hostingSingapore (data centre); company established in the Republic of Lithuania
Kit (Kit.com, Inc., formerly ConvertKit)Mailing list and newsletter delivery (see Section 11)United States
MicrosoftEmail and productivity servicesUnited States, and other countries in which Microsoft operates data centres

5.2.1. We take reasonable steps to ensure that any overseas recipient deals with your personal information in a manner consistent with the Australian Privacy Principles, as required by Australian Privacy Principle 8. Those steps include selecting providers that publish binding data protection commitments, restricting the categories of personal information disclosed to each provider to what that service requires, and reviewing this Policy whenever a provider changes.

5.2.2. Under Australian Privacy Principle 8.1 we remain accountable for personal information disclosed to an overseas recipient. An act or practice of an overseas recipient that would breach the Australian Privacy Principles is taken to be a breach by us.

5.2.3. If you would prefer that your personal information not be disclosed overseas, contact us at privacy@beneaththesurface.au. Some services cannot be provided without such disclosure, and we will tell you where that is the case.

5.3. We may from time to time need to disclose personal information to comply with a legal requirement, such as a law, regulation, court order, subpoena, warrant, in the course of a legal proceeding or in response to a law enforcement agency request.

5.4. We may also use your personal information to protect the copyright, trademarks, legal rights, property, or safety of Beneath the Surface AU, beneaththesurface.au, its customers, or third parties.

5.5. If there is a change of control in our business or a sale or transfer of business assets, we reserve the right to transfer to the extent permissible at law our user databases, together with any personal information and non-personal information contained in those databases.


6. Security, retention, and data breach notification

6.1. Beneath the Surface AU is committed to ensuring that the information you provide to us is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic, and managerial procedures to safeguard and secure information and protect it from misuse, interference, loss and unauthorised access, modification, and disclosure.

6.2. The transmission and exchange of information is carried out at your own risk. We cannot guarantee the security of any information that you transmit to us, or receive from us. Although we take measures to safeguard against unauthorised disclosures of information, we cannot assure you that personal information that we collect will not be disclosed in a manner that is inconsistent with this Privacy Policy.

6.3. Clause 6.2 describes the practical limits of any security measure. It does not limit our obligations under the Privacy Act 1988 (Cth), or the commitments set out in this section.

6.4. Application of the Notifiable Data Breaches scheme: The Privacy Act 1988 (Cth) does not apply to a small business operator with an annual turnover of $3 million or less, unless an exception applies. Beneath the Surface AU is below that threshold. We apply the Notifiable Data Breaches scheme in Part IIIC of the Act as a minimum standard to all personal information we hold, whether or not the Act requires it of us. The commitments in this section are given, and will be met, on that basis.

6.5. What a data breach is: A data breach occurs where personal information we hold is subject to unauthorised access or unauthorised disclosure, or is lost. Examples include a lost or stolen device, an email sent to the wrong recipient, and unauthorised access to our website database or our mailing list.

6.6. Eligible data breach: A data breach is an eligible data breach where it is likely to result in serious harm to one or more individuals, and we have not prevented that harm through remedial action (sections 26WE and 26WF). Serious harm includes serious physical, psychological, emotional, financial, or reputational harm. Whether serious harm is likely is assessed against matters including the kind and sensitivity of the information, the protections in place, and the persons who have obtained or could obtain access (section 26WG).

6.7. Assessment: Where we have reasonable grounds to suspect that an eligible data breach may have occurred, we will carry out a reasonable and expeditious assessment, and will take all reasonable steps to complete that assessment within 30 calendar days of becoming aware of those grounds (section 26WH). Where we have reasonable grounds to believe that an eligible data breach has occurred, we proceed directly to notification.

6.8. Notification: Where notification is required, we will prepare a statement and give it to the Office of the Australian Information Commissioner (OAIC) as soon as practicable, and we will notify the individuals at risk of serious harm (sections 26WK and 26WL). Where it is not practicable to notify each individual, we will publish the statement and take reasonable steps to publicise its contents.

6.9. What a notification contains: A notification will set out our identity and contact details, a description of the data breach, the kinds of information concerned, and our recommendations about the steps you should take in response (section 26WK).

6.10. Records of data breaches: We keep a record of each suspected or actual data breach, the assessment carried out, and the action taken.

6.11. Retention and destruction: We retain personal information only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires. When it is no longer needed, we destroy it or de-identify it.

6.12. Retention periods: The following periods apply. Where a period is set by another Beneath the Surface AU policy, that policy is named.

RecordRetention period
Records from previous client engagements7 years from the last service provided
Website enquiry submissions2 years, unless the enquiry becomes an engagement
Mailing list consent and unsubscribe recordsAt least 3 years, under the Anti-Spam Compliance Policy
Pre-engagement confirmations from host organisationsAt least 7 years, under the Child Safety Policy
Child safety incident, disclosure, and complaint recordsRetained indefinitely, under the Child Safety Policy
Records of data breaches7 years

6.13. Reporting a suspected breach: If you believe that personal information we hold about you has been lost, accessed without authorisation, or disclosed without authorisation, contact us at privacy@beneaththesurface.au.


7. Access to your personal information

7.1. You may request details of personal information that we hold about you in accordance with the provisions of the Privacy Act 1988 (Cth). A small administrative fee may be payable for the provision of information. If you would like a copy of the information which we hold about you or believe that any information we hold on you is inaccurate, out of date, incomplete, irrelevant, or misleading, please email us at privacy@beneaththesurface.au.

7.2. We reserve the right to refuse to provide you with information that we hold about you in certain circumstances set out in the Privacy Act.


8. Complaints about privacy

8.1. If you have any complaints about our privacy practices, please feel free to send in details of your complaints to PO Box 48, Ballajura, Western Australia, Australia, 6066. We take complaints very seriously and will respond shortly after receiving written notice of your complaint.

8.2. If you are not satisfied with the outcome of your complaint, or if we fail to respond to your complaint within 30 days, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC).


9. Changes to Privacy Policy

9.1. Please be aware that we may change this Privacy Policy in the future. We may modify this Policy at any time, in our sole discretion and all modifications will be effective immediately upon our posting of the modifications on our website or notice board. Please check back from time to time to review our Privacy Policy.


10. Website and Tracking Technologies

10.1. Website Hosting: Our website is hosted by Hostinger International Ltd, a company established in the Republic of Lithuania. Our site and its database are stored on Hostinger infrastructure located in Singapore. Information you submit through our website, including through contact and enquiry forms, is stored on that infrastructure. See Section 5.2 for our overseas disclosure obligations.

10.2. Analytics and Session Recording: We do not use behavioural analytics, heatmapping, or session-recording tools on our website. We do not use Microsoft Clarity, Microsoft Advertising, or any comparable product that records how you move through, click within, or interact with our pages. We do not use your website activity for advertising or remarketing, and we do not sell or disclose it to advertising networks.

10.3. Cookies: We may from time to time use cookies on our website. Cookies are very small files which a website uses to identify you when you come back to the site and to store details about your use of the site. Most web browsers automatically accept cookies but you can choose to reject cookies by changing your browser settings. However, this may prevent you from taking full advantage of our website.

10.4. Third party sites: Our site may from time to time have links to other websites not owned or controlled by us. These links are meant for your convenience only. Links to third party websites do not constitute sponsorship or endorsement or approval of these websites. Please be aware that Beneath the Surface AU is not responsible for the privacy practices of other such websites. We encourage our users to be aware, when they leave our website, to read the privacy statements of each and every website that collects personal identifiable information.


11. Mailing List and Email Service Provider

11.1. Our newsletter and mailing list are managed using Kit (kit.com, operated by Kit.com, Inc., formerly ConvertKit), a service based in the United States. Kit is a separate service from our website host and from our email and productivity provider, and this section describes it specifically.

11.2. What Kit receives: if you subscribe to our mailing list, the personal information you provide at sign-up, typically your name and email address, is stored by Kit, together with a record of your subscription. Kit also records delivery and engagement information about the messages we send you, such as whether a message was delivered, opened, or a link within it was clicked.

11.3. Why we use it: to deliver the newsletter you asked for, to send any resource offered at sign-up, and to manage subscriptions and unsubscribe requests reliably.

11.4. Overseas disclosure: subscribing to our mailing list involves the disclosure of your personal information to a recipient located in the United States. This is an overseas disclosure for the purposes of Australian Privacy Principle 8, and Sections 5.2.1 and 5.2.2 apply to it. Kit publishes contractual data protection commitments, including Standard Contractual Clauses, and participates in the EU–U.S. Data Privacy Framework.

11.5. What Kit does not receive: we do not disclose to Kit any sensitive information as defined in Section 1.3, any information collected for academic research, or any client records or material you provide in the course of receiving our services. Mailing list data is kept separate from those records.

11.6. Consent and unsubscribing: we add you to the mailing list only where you have provided consent, and every message includes a working unsubscribe link. Unsubscribing removes you from the list and stops further commercial messages. Our obligations under the Spam Act 2003 (Cth), covering consent, sender identification, and unsubscribe, are set out in the Anti-Spam Compliance Policy.

11.7. Access and deletion: you may ask us at any time what information is held about you on the mailing list, or ask for it to be deleted, by emailing privacy@beneaththesurface.au. Section 7 applies.

11.8. If we change mailing list providers, this section will be updated and the version of this Policy incremented before the new provider is used.